PT-2026-78894 · WordPress · Kirki
CVE-2026-74992
·
Published
2026-08-20
·
Updated
2026-08-20
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Kirki versions prior to 6.2.3
Description
Users with the Editor role can upload arbitrary files to a web accessible directory because the plugin fails to properly validate files within uploaded archives and does not remove unwanted files after extraction. This flaw can lead to Stored XSS (Cross-Site Scripting, where malicious scripts are permanently stored on the server) and RCE (Remote Code Execution, allowing an attacker to execute arbitrary commands) on certain server configurations.
Recommendations
Update Kirki to version 6.2.3 or later.
Exploit
Fix
RCE
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kirki